Impact
The vulnerability resides in the OTP Validation component of Releasit COD Form & Upsells version 1. By manipulating the client‑side handling of one‑time passwords, an attacker can cause the application to rely on data supplied by the client instead of performing the intended server‑side verification. This flaw turns server‑side security controls into a flag that can be toggled by the user, effectively bypassing authentication and permitting access to coupon or upsell functionality that is normally gated by merchant code. The weakness is identified as CWE‑602, which describes the improper reliance on client‑side validation for securing a system.
Affected Systems
The affected product is Releasit COD Form & Upsells v1, distributed by the vendor Releasit. The SOP includes a client‑side OTP enforcement module that is missing in the upgraded v2 release; upgrading to that version removes the problematic component and reinstates proper server‑side OTP checks. No other versions were listed as vulnerable in the CNA data, so at present only v1 is known to be affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available, which means the exploitation probability is not quantified. The vulnerability is not listed in CISA’s KEV catalog, so no wide‑scale exploitation has been reported. However, the description explicitly states that the attack may be launched remotely and that the exploit has already been made public. Because the flaw is client‑side, once the vulnerability is known it can be exploited with minimal effort and without special access, elevating the operational risk for merchants running affected installations.
OpenCVE Enrichment